CVE-2018-25149: Microhardcorp Bullet-3g Firmware

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a specially crafted page.

Affected products

Published 2025-12-24. Last modified 2026-06-17.